CVE-2026-89003 PUBLISHED

WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview

Assigner: WPScan
Reserved: 10.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.

Product Status

Vendor Unknown
Product WPeMatico RSS Feed Fetcher
Versions Default: unaffected
  • affected from 0 to 2.8.27 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE